Everest Themes Everest Backup Cross-Site Request Forgery Vulnerability Allowing Path Traversal

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Everest Backup plugin for WordPress, specifically in versions through 2.3.9. This vulnerability allows for Path Traversal attacks.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of the user, potentially allowing an attacker to manipulate files or directories in a way that is not normally permitted.

Added: Dec 31, 2025, 9:17 AM
Updated: Dec 31, 2025, 9:17 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
6.5
remediation
0.0
relevance
1.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.